CVE-2026-107573: Incorrect Default Permissions in hMailServer

Published Oct 8, 2026
·
Updated

Incorrect default permissions in the Windows installer of Progressive Robot hMailServer 6.0.0 through 6.3.5 allow a local authenticated user to read the mail server's data. The installer created the data, log, temp, database and event folders and the hMailServer.INI configuration file with the permissions inherited from the installation folder, by default under Program Files, which give the local Users group read access. Any user who can sign in to the computer could read every stored message, the logs, the built-in database with the accounts' password hashes whenever the service is stopped, and the configuration file, including the database password, which is sealed only with the machine's DPAPI key and can be unsealed by any local account; with an external database that password gives full control of it. The Linux AppImage of 6.3.0 through 6.3.5 likewise created its per-user data folders readable by other local users.

Affected Software

2 affected components
Progressive Robot hMailServer>=6.0.0<=6.3.5
Progressive Robot hMailServer>=6.3.0<=6.3.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade hMailServer to a version that resolves this vulnerability.

    Fixed in 6.3.6
  2. Configuration

    From an elevated prompt, remove the inherited entries for Users and the application package groups using icacls with /inheritance:d, then /remove:g.

    hMailServer data, log, temp, database, and event folders plus hMailServer.INI Windows filesystem permissions = Remove inherited Users and application package group entries
  3. Operational

    Change the database password and the administrator password if accounts that are not administrators could sign in to the server.

Event History

Oct 8, 2026
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
RemedyDescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203